¡¾Â©¶´¸üС¿Linux Kernel ksmbd 12Ô¶à¸öÄþ¾²Â©¶´
Ðû²¼Ê±¼ä 2022-12-280x00 ©¶´¸ÅÊö
Linux Kernel ÊÇ¿ªÔ´²Ù×÷ϵͳ Linux ËùʹÓõÄÄںˡ£KSMBD ÊÇÒ»¸ö linux Kernel ·þÎñÆ÷£¬ËüÔÚÄں˿ռäÖÐʵÏÖ SMB3 ÐÒ飬ÓÃÓÚͨ¹ýÍøÂç¹²ÏíÎļþ¡£
½üÈÕ£¬Linux Kernel ksmbd±»Åû¶´æÔÚ¶à¸öÄþ¾²Â©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´¿ÉÄܵ¼ÖÂÐÅϢй¶¡¢¾Ü¾ø·þÎñ»òÔ¶³Ì´úÂëÖ´Ðеȡ£
0x01 ©¶´ÏêÇé
CVE | ±êÌâ | ÆÀ·Ö | ˵Ã÷ | Ó°Ï췶Χ |
CVE-2022-47939 | Linux Kernel ksmbd UAFÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨ÑÏÖØ£© | 10.0 | ¸Ã©¶´´æÔÚÓÚSMB2_TREE_DISCONNECT ÃüÁîµÄ´¦Öùý³ÌÖУ¬ÓÉÓÚÔÚ¶Ô¹¤¾ßÖ´ÐвÙ×÷֮ǰûÓÐÑéÖ¤¹¤¾ßÊÇ·ñ´æÔÚ£¬¿ÉÔÚδ¾Éí·ÝÑéÖ¤µÄÇé¿öÏÂÀûÓø鶴ÔÚÄÚºËÉÏÏÂÎÄÖÐÖ´ÐдúÂë¡£ | 5.15 ¡Ü Linux Kernel < 5.19.2 |
CVE-2022-47940 | Linux Kernel ksmbdÔ½½ç¶ÁÈ¡ÐÅϢ鶩¶´£¨ÑÏÖØ£© | 9.6 | Linux Kernel °æ±¾5.15µ½5.18.18֮ǰ£¬ÓÉÓÚsmb2_write() ÎÞ·¨ÑéÖ¤Óû§ÌṩµÄÊý¾Ý£¬¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡£¬¾¹ýÑéÖ¤µÄ¶ñÒâÓû§¿ÉÀûÓø鶴й¶Linux Äں˰²×°µÄÃô¸ÐÐÅÏ¢¡£×¢£º¸Ã©¶´¿É½áºÏÆäËü©¶´ÊµÏÖÔÚÄÚºËÉÏÏÂÎÄÖÐÖ´ÐÐÈÎÒâ´úÂë¡£ | 5.15 ¡Ü Linux Kernel < 5.18.18 |
CVE-2022-47943 | Linux Kernel ksmbdÔ½½ç¶Áȡ©¶´£¨ÑÏÖØ£© | 9.6 | Linux Kernel °æ±¾5.15µ½5.19.2֮ǰÔÚsmb2_write()´¦ÖÃÖдæÔÚ©¶´£¬µ±DataOffsetΪ0ÇÒLengthÌ«´óʱ¿ÉÄܵ¼ÖÂÔ½½ç¶ÁÈ¡¡£ | 5.15 ¡Ü Linux Kernel < 5.19.2 |
CVE-2022-47942 | Linux Kernel ksmbd »ùÓڶѵĻº³åÇøÒç³öÔ¶³Ì´úÂëÖ´ÐЩ¶´£¨¸ßΣ£© | 8.5 | Linux Kernel °æ±¾5.15µ½5.19.2֮ǰ£¬ÓÉÓÚÔÚ½«Óû§ÌṩµÄÊý¾Ý¸´ÖƵ½»ùÓڶѵĻº³åÇø֮ǰûÓжÔÓû§ÌṩµÄÊý¾ÝµÄ³¤¶È½øÐÐÊʵ±ÑéÖ¤£¬µ¼Ö¶ѻº³åÇøÒç³ö£¬¾¹ýÑéÖ¤µÄ¶ñÒâÓû§¿ÉÀûÓø鶴ÔÚÊÜÓ°ÏìµÄ Linux Äں˰²×°ÉÏÖ´ÐÐÈÎÒâ´úÂë¡£ | 5.15 ¡Ü Linux Kernel < 5.19.2 |
CVE-2022-47941 | Linux Kernel ksmbdÄÚ´æºÄ¾¡¾Ü¾ø·þÎñ©¶´£¨ÖÐΣ£© | 5.3 | ¸Ã©¶´´æÔÚÓÚ SMB2_NEGOTIATE ÃüÁîµÄ´¦ÖÃÖУ¬ÓÉÓÚÓÐЧÉúÃüÖÜÆÚºóÄÚ´æÊͷŲ»×㣬¿ÉÒÔÀûÓø鶴µ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´Ó°ÏìÁËLinux Kernel 5.15µ½5.19.2֮ǰµÄ°æ±¾¡£ | 5.15 ¡Ü Linux Kernel < 5.19.2 |
CVE-2022-47938 | Linux Kernel ksmbdÔ½½ç¶ÁÈ¡¾Ü¾ø·þÎñ©¶´£¨ÖÐΣ£© | 6.5 | ÔÚ CIFS ÎļþϵͳÖд¦Öà SMB2_TREE_CONNECT ÃüÁîʱ£¬ÓÉÓÚȱ·¦¶ÔÓû§ÌṩµÄÊý¾ÝµÄÕýÈ·ÑéÖ¤£¬¿ÉÄܵ¼Ö¶ÁÈ¡³¬³öÒÑ·ÖÅ仺³åÇøµÄĩ⣬¿ÉÒÔÀûÓø鶴ÔÚϵͳÉϵ¼Ö¾ܾø·þÎñ¡£¸Ã©¶´Ó°ÏìÁËLinux Kernel 5.15µ½5.19.2֮ǰµÄ°æ±¾¡£ | 5.15 ¡Ü Linux Kernel < 5.19.2 |
Ó°Ï췶Χ
5.15 ¡Ü Linux Kernel < 5.18.18
5.15 ¡Ü Linux Kernel < 5.19.2
0x02 Äþ¾²½¨Òé
Ä¿Ç°ÕâЩ©¶´ÒѾÐÞ¸´£¬ÊÜÓ°ÏìÓû§¿ÉÉý¼¶µ½5.15.61¡¢5.19.2»ò¸ü¸ß°æ±¾¡£
ÏÂÔØÁ´½Ó£º
https://kernel.org/
»º½â´ëÊ©£º
Èç¹û´æÔÚÇÒÆôÓÃÁËksmbd Ä£¿é£¬¿É½ûÓà ksmbd Ä£¿é¡£
×¢£ºLinuxϵͳÓû§¿ÉÒÔͨ¹ý¼ì²ìϵͳ°æÔÀ´Åжϵ±Ç°ÏµÍ³ÊÇ·ñÔÚÊÜÓ°Ï췶ΧÄÚ£¬Èôϵͳ°æ±¾ÔÚÊÜÓ°Ï췶ΧÄÚ£¬ÇÒϵͳÆôÓÃÁËksmbdʱ£¬ÔòÒ×ÊÜÉÏÊö©¶´Ó°Ïì¡£
ÕâЩ©¶´Ó°ÏìÆôÓÃÁË ksmbd µÄ SMB ·þÎñÆ÷£¬Ê¹Óà Samba µÄSMB ·þÎñÆ÷²»ÊÜÓ°Ï죨´ó¶àÊýÓû§£©¡£
0x03 ²Î¿¼Á´½Ó
https://www.openwall.com/lists/oss-security/2022/12/23/10
https://www.zerodayinitiative.com/advisories/ZDI-22-1690/
https://bugzilla.redhat.com/show_bug.cgi?id=2155943
0x04 °æ±¾ÐÅÏ¢
°æ±¾ | ÈÕÆÚ | ÐÞ¸ÄÄÚÈÝ |
V1.0 | 2022-12-28 | Ê×´ÎÐû²¼ |
0x05 ¸½Â¼
¶¶È¦Îª¶Ä¶øÉú¼ò½é
¶¶È¦Îª¶Ä¶øÉú½¨Á¢ÓÚ1996Ä꣬ÊÇÓÉÁôÃÀ²©Ê¿ÑÏÍû¼ÑŮʿ´´½¨µÄ¡¢ÓµÓÐÍêÈ«×ÔÖ÷֪ʶ²úȨµÄÐÅÏ¢Äþ¾²¸ß¿Æ¼¼ÆóÒµ¡£ÊǹúÄÚ×î¾ßʵÁ¦µÄÐÅÏ¢Äþ¾²²úÎï¡¢Äþ¾²·þÎñ½â¾ö·½°¸µÄÁ캽ÆóÒµÖ®Ò»¡£
¹«Ë¾×ܲ¿Î»ÓÚ±±¾©ÊÐÖйشåÈí¼þÔ°¶¶È¦Îª¶Ä¶øÉú´óÏ㬹«Ë¾Ô±¹¤6000ÓàÈË£¬Ñз¢ÍŶÓ1200ÓàÈË, ¼¼Êõ·þÎñÍŶÓ1300ÓàÈË¡£ÔÚÈ«¹ú¸÷Ê¡¡¢ÊС¢×ÔÖÎÇøÉèÁ¢·ÖÖ§»ú¹¹ÁùÊ®¶à¸ö£¬ÓµÓÐÁýÕÖÈ«¹úµÄÏúÊÛÌåϵ¡¢ÇþµÀÌåϵºÍ¼¼ÊõÖ§³ÖÌåϵ¡£¹«Ë¾ÓÚ2010Äê6ÔÂ23ÈÕÔÚÉîÛÚÖÐС°å¹ÒÅÆÉÏÊС££¨¹ÉƱ´úÂ룺002439£©
¶àÄêÀ´£¬¶¶È¦Îª¶Ä¶øÉúÖÂÁ¦ÓÚÌṩ¾ßÓйú¼Ê¾ºÕùÁ¦µÄ×ÔÖ÷´´ÐµÄÄþ¾²²úÎïºÍ×î¼Ñʵ¼ù·þÎñ£¬×ÊÖú¿Í»§È«ÃæÌáÉýÆäIT»ù´¡ÉèÊ©µÄÄþ¾²ÐÔºÍÉú²úЧÄÜ£¬Îª´òÔìºÍÌáÉý¹ú¼Ê»¯µÄÃñ×åÐÅÏ¢Äþ¾²¹¤ÒµÁì¾üÆ·Åƶø²»Ð¸Å¬Á¦¡£
¹ØÓÚ¶¶È¦Îª¶Ä¶øÉú
¶¶È¦Îª¶Ä¶øÉúÄþ¾²Ó¦¼±ÏìÓ¦ÖÐÐÄÖ÷ÒªÕë¶ÔÖØÒªÄþ¾²Â©¶´µÄÔ¤¾¯¡¢¸ú×ٺͷÖÏíÈ«Çò×îеÄÍþвÇ鱨ºÍÄþ¾²³ÂËß¡£
¹Ø×¢ÒÔϹ«Öںţ¬»ñÈ¡È«Çò×îÐÂÄþ¾²×ÊѶ£º